Previous Article Back to Blog
September 8, 2026 Kévin Lefèvre (Consultant & AI Expert) 8 min read AI Act

High-Risk AI Classification: The 7-Step Test (2026)

Executive Summary
  • On 19 May 2026, the European Commission released its draft guidelines on high-risk AI classification under Article 6(5) of the AI Act: the clearest official benchmark to date, still subject to stakeholder consultation as of this writing.
  • Most SMEs default to one of two wrong answers: "none of our AI is high-risk," assumed rather than verified, or "it probably all is," which leads to paralysis. Neither survives a structured test.
  • Having a human in the loop does not automatically declassify a high-risk system. The Commission's guidance is explicit on this point, and it is the single most common misunderstanding we encounter in customer conversations.
8
Annex III Categories

covering the areas where an AI system can be classified as high-risk, from employment to essential services.

€35M
Maximum Fine

or 7% of annual worldwide turnover, for non-compliance with prohibited practices, the highest penalty tier under the AI Act.

High risk, in brief: the AI Act does not classify AI tools by brand name or broad category. It classifies specific systems by their intended purpose. The same underlying model can be low-risk in one application and high-risk in another, depending on what it actually helps decide.

Key Takeaways

  • Classification is based on intended purpose, not marketing claims or general capability. A system marketed as an "efficiency tool" can still fall into a high-risk category if its actual use sits within Annex III.
  • General-purpose tools like Copilot, ChatGPT-based integrations, or similar LLM-powered products are not automatically high-risk, but a specific deployment of them can be, depending on what it is used for.
  • Modular or agentic AI systems that jointly serve a high-risk purpose are treated as a single system under the Commission's May 2026 guidance . You cannot break a workflow into pieces to avoid classification.

Why This Test, and Why Now

Annex III of the AI Act lists the categories where an AI system can be classified as high-risk, but reading that list does not answer the question most businesses actually have: does our specific use case fall into it? That is precisely the gap the European Commission's draft guidelines, published on 19 May 2026 after a delay from the initial February target, were written to fill. They do not change the law. They clarify how it applies, with a level of practical detail that was previously missing.

Consider a mid-sized recruitment agency that uses three different tools: one to screen resumes, one to draft rejection emails, and one to rank shortlisted candidates by fit score. Each tool, considered in isolation, looks narrow enough that someone might pass it over. Used together in a single hiring decision, they present a very different question, and Step 6 below explains why.

The test below reflects the Commission's logic, organized into seven sequential checks. Run it per AI system, per use case, not once for "our company's AI" as a whole. That question does not have a single answer.

The 7-Step Test

Step 1: Is It Actually an "AI System" Under the Act?

Article 3(1) defines an AI system as a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments, with varying levels of autonomy or adaptiveness. A simple rule-based spreadsheet macro is not one. A machine learning model that makes recommendations, generates content, or scores candidates almost certainly is. If the answer is no, stop here: the Act does not apply to this tool.

Step 2: Is It a Prohibited Practice Under Article 5?

Before checking for high risk, rule out the small number of practices that are banned outright: manipulative techniques that cause harm, social scoring, certain biometric categorization, and similar practices. These carry the highest penalty tier under the Act, up to €35M or 7% of worldwide turnover, and are rare in typical SME use. The check takes thirty seconds and should never be skipped.

Step 3: Is It a Safety Component of an Already-Regulated Product?

Some AI systems are high-risk because they are safety components of products already covered by EU product safety legislation (machinery, medical devices, toys, and similar), independent of Annex III. Most internal SME software and tools sit outside this category, but any AI embedded into a physical product needs to be checked specifically here.

Step 4: Does Its Intended Use Fall Under an Annex III Category?

This is the core test. Annex III lists eight domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services (including credit scoring and insurance risk assessment), law enforcement, migration and border control, and the administration of justice and democratic processes. If your AI system's actual, intended use sits inside one of these, an AI tool used to screen or rank job applicants, for example, move to Step 5.

Step 5: Does It Materially Influence the Outcome, or Just Assist a Human Who Reviews It?

Article 6(3) provides exemptions where the system doesn't pose a significant risk to health, safety, or fundamental rights, typically because it performs a narrow procedural task, improves a completed human activity, or detects patterns without informing a decision. This is where most companies get it wrong. A human clicking "approve" on an AI-generated shortlist isn't, by itself, enough to exit high-risk classification if the AI's output is what substantively shapes the decision. The Commission's May 2026 guidance is explicit: including a human in the loop does not automatically declassify a system.

Step 6: Is It Part of a Modular or Agentic System That Jointly Serves a High-Risk Purpose?

Increasingly relevant as companies chain AI tools together, like the recruitment agency above: one model screening resumes, another drafting rejection emails, a third scheduling interviews. If the linked components jointly serve a high-risk purpose, the Commission's guidance treats the overall configuration as one system. You can't decompose a high-risk workflow into individually "safe" pieces to avoid classification.

Step 7: Document the Answer, Whichever It Is

Whether a system lands as high-risk or not, write down the reasoning, the date, and the evidence used, including promotional materials and technical documentation, which the guidance notes can inform how intended use is determined. A negative classification without documentation is indistinguishable, to a regulator, from a classification nobody ever performed.

Quick-Reference Table

Step Question If yes If no
1 Is it an AI system under Art. 3(1)? Continue Act doesn't apply, stop
2 Is it a prohibited practice (Art. 5)? Stop, do not deploy Continue
3 Is it a safety component of a regulated product? High-risk, continue to obligations Continue
4 Does intended use fall under Annex III? Continue Not high-risk via Annex III, document and stop
5 Does it materially shape the outcome (not just assist review)? Continue May qualify for Art. 6(3) exemption, document carefully
6 Is it part of a modular system jointly serving a high-risk purpose? Treat the whole configuration as high-risk Continue
7 (final step, both branches) Document the classification and evidence, either way Document the classification and evidence, either way

Frequently Asked Questions

Does using ChatGPT, Copilot, or another general-purpose AI tool automatically make us high-risk?
No. General-purpose AI models aren't automatically classified as high-risk. What matters is the specific, intended use you put them to. Using Copilot to draft internal emails is different from using an AI-based tool to screen job applicants. The second is far more likely to fall under Annex III.
If a human reviews every AI recommendation before acting, are we exempt from high-risk classification?
Not automatically. The Commission's May 2026 draft guidance is explicit that human review alone doesn't declassify a system. What matters is whether the AI output materially shapes the outcome. A human rubber-stamping an AI-generated shortlist is a different situation from a human independently evaluating candidates with AI as one input among several.
We use three separate tools that together handle recruitment. Does each one need to be classified separately?
Check the whole configuration, not just each component. If the linked tools jointly serve a high-risk purpose, and recruitment falls under Annex III, the Commission's guidance treats them as one system for classification purposes, even if no individual tool looks high-risk in isolation.
What happens if we classify a system as high-risk?
High-risk classification triggers a distinct set of obligations under the Act, including risk management, data governance, technical documentation, human oversight design, and, for deployers specifically, obligations under Article 26 such as record-keeping and monitoring. This article covers classification only; the obligations that follow are a separate, more extensive compliance workstream.
Kévin Lefèvre

Kévin Lefèvre is a Data Scientist specializing in multimodal document intelligence and large-scale AI pipelines, and an expert AI consultant at Themio, ensuring every platform recommendation is fully traceable to its legal source. EPITA engineering graduate, AWS and Deep Learning certified.

Themio.ai maps your AI tools and use cases against the AI Act (Annexes I and III, Article 6 exemptions) and produces the technical classification documentation required by EU regulators (see our 5-step AI Act compliance guide ). See how Themio works →